Security
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
-
iker-gonzalez Skill Antwork VoiceUse when the user wants to build, refresh, or audit a per-account voice profile in Antwork so drafts sound like them — including analyzing their existing posts to extract tone, capturing brand voice for a new account, or fixing AI-sounding drafts. Trigger on phrases like "learn my voice", "match my writing style", "my posts sound like a robot", "set up my brand voice", "refresh my voice profile", "analyze my LinkedIn tone", or any request to make Antwork posts sound on-brand.
-
kemalcr Skill Kemal WebsocketImplementing real-time bi-directional communication with WebSockets in Kemal, origin security, and lifecycle management.
Audited -
kubernetes-sigs Bundle Fix Image CvesScan a built container image with Trivy, classify fixable Go-module and base-image CVEs, apply dependency and Dockerfile fixes, and verify the result with file checks and an optional image rescan. Use when the user wants to fix CVEs in a container image, scan for vulnerabilities, or mentions Trivy, CVE remediation, image security, or dependency vulnerabilities.
Audited -
kuya-egg Bundle KodawariReview software with careful attention to correctness, maintainability, security, operations, and meaningful detail. Use for diffs, branches, pull requests, architecture decisions, or final quality checks.
-
lancetw Bundle Bible Fact CheckSystematically review biblical content through a 10-point quality checklist. Works with bible-buddy reference files, any file path, URLs, or text pasted directly in the conversation. Use when asked to review, audit, check, or verify biblical content. Trigger on: "檢查冷知識", "fact check", "檢查經文", "review bible", "幫我檢查這段", "bible-fact-check", or any request to find errors, duplicates, or issues in biblical reference content.
-
liueggy Skill Qt UI DesignDesign or audit UI for Qt/QML, Qt projects, web, or embedded MPU or MCU targets. Use when creating screens, layouts, navigation, or auditing UX.
Audited -
liueggy Bundle Qt Qml ReviewInvoke when the user asks to review, check, audit, or look over Qt5 QML code -- or suggest before committing. Runs deterministic linting (47+ rules) then six parallel deep- analysis agents covering bindings, layout, loaders, delegates, states, and performance. Designed for Qt5 QML code. Reports only high-confidence issues (>80/100) with structured mitigations. Read-only -- never modifies code.
Audited -
lizliz404 Bundle Video Script ConversionUse when Liz asks article→口播脚本 conversion, 修整/实录修整已有口语稿, or audit/compare candidate scripts.
Audited -
logseq Bundle Logseq Dependency UpgradeAudit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions, cross-root consistency, lockfile resolution, deprecation, staleness, and OSV vulnerabilities, then generating a batch-ordered upgrade plan and compact JSON artifact.
Audited -
loonghao Skill Code ReviewerReviews a pull request or diff and produces structured feedback on correctness, security, performance, and style.
-
wangjunqing-coder Skill Super Dev Security全栈之神·安全审计官。供应链安全门禁、依赖扫描、代码安全自查。
-
bmcgauley Bundle Adsense AuditComprehensive Google AdSense compliance audit skill. This skill should be used when a user wants to audit a website for AdSense approval, troubleshoot a "Low Value Content" rejection, assess policy violations, or improve a site's eligibility for Google AdSense monetization. Applies to new applicants, rejected sites, and sites seeking to improve ad performance.
Audited -
datadog Skill LintRun targeted linting, formatting, and code quality checks on modified files. Use this to validate code style, type safety, security, and other quality metrics before committing. Supports running all checks or targeting specific checks on specific files for efficient validation.
-
makerjackie Bundle Mj Cf DnsMaintain Cloudflare DNS and domain bindings safely. Use when a user asks to add, update, delete, verify, or audit Cloudflare DNS records; point a domain or subdomain at a Cloudflare Pages `*.pages.dev` site; bind a custom domain to a Pages project; configure a Worker custom domain through Wrangler `custom_domain: true`; fix DNS conflicts; or verify Cloudflare nameserver propagation.
-
mindgames Bundle Gh Pr AuditPerform a full local audit of one or more GitHub PRs, run repository-native deterministic checks, apply result labels, and post a structured review comment. Use when a PR in this repo or under projects/* needs a deep, evidence-based review across any language or stack.
Audited -
mindgames Bundle Github Pull Request Review ResolveDeeply audit a GitHub pull request, analyze review comments and threads, apply legitimate fixes, resolve addressed review threads, and repair failing CI/build checks. Use when asked to handle PR review feedback, close out reviewer comments, or fix failing PR checks before merge.
-
moonshotai Skill Worktree StatusAudit all git worktrees in the current project. Use when the user asks about worktree status, which branches are merged, which have uncommitted changes, or which worktrees can be safely cleaned up.
-
luisurrutia Bundle Github ActionsHarden GitHub Actions and Dependabot: create or modify workflow YAML, reusable workflows, or .github/dependabot.yml; configure dependency updates, alerts, graphs, private registries, and pull-request automation; audit security, correctness, reliability, cost, or performance.
-
lukehle Skill Code QuorumAdversarial review of a change, a pull request, or a subsystem - lenses for correctness under adversarial input, failure modes, interface and migration risk, operability, and test honesty, with an evidence contract that demands a reproducing case rather than a code smell. Trigger on "review this PR", "review the code", "before I merge", "is this safe to ship", "code review", "audit this subsystem", "what could break".
-
mateobogo Skill Solve ChallengeSolves CTF challenges by analyzing files, connecting to services, and applying exploitation techniques. Orchestrates category-specific CTF skills for pwn, crypto, web, reverse engineering, forensics, OSINT, malware analysis, and miscellaneous challenges. Use when given a CTF challenge to solve, a challenge file to analyze, or a service endpoint to exploit.
Audited -
mosofin Skill Month End Close ChecklistUse this skill whenever the user wants to plan, run, or audit a monthly close against their Mosofin workspace. Triggers include: 'run the month-end close', 'month-end checklist', 'what's left to close', 'close calendar', 'organize the close for [month]', 'close coordination', or any orchestration of the periodic close process. Workspace-scoped: it confirms the workspace, discovers which company files are connected and which read-only tools are enabled, then scopes the checklist from the entity's actual chart of accounts, pre-populates the status of every task that leaves ledger evidence, and runs the final tie-out including inter-period continuity. Do NOT use for an individual close task (a specific reconciliation, accrual, or JE) — use the corresponding specific skill. Outputs a comprehensive close checklist with owners, deadlines, dependencies, status tracking, a final tie-out workpaper, and a coverage sheet.
-
olaradiallysymmetrical491 Skill Web3 Start HereMaster index for the web3 smart contract security knowledge base. Use this to navigate the skill chain. Read files in order — each ends with NEXT.
-
olaradiallysymmetrical491 Skill Web3 Poc FoundryComplete Foundry PoC writing guide + all cheatcodes + DeFiHackLabs reproduction patterns. Use this when building a proof of concept exploit, setting up a fork test, using Foundry cheatcodes, or reproducing a known DeFi hack for learning.
-
olaradiallysymmetrical491 Skill Web3 Hunt Zksync EraZKsync Era (Immunefi) completed hunt — 0 findings after exhaustive 5-session audit. Use as a DEFENSE STUDY — learn what makes a protocol unhuntable, which patterns block all 10 bug classes, and when to abandon a target. Contains architecture breakdown, 25 tested attack vectors, and pre-dive scoring refinements for large L1 bridge protocols.
-
reinamaccredy Bundle Maestro CouncilLead-only council for a hard-to-reverse fork - a neutral brief, sealed independent seats, one premise verifier on unanimity, bounded verifiers, one cross-examination round, a draft-verdict audit, and one binding verdict recorded as a decision with its dissent. Never inside a seat.
-
sanjithbolloju18 Bundle Criticism Self Criticism触发:当一项工作已经完成、进入阶段验收、收到批评反馈,或反复出现同类错误需要系统纠偏时调用;常见信号包括 review、audit、retrospective、quality check、纠错与复盘。 English: Trigger after delivery or at a review checkpoint when quality must be examined honestly and errors must be corrected without defensiveness. Use this skill for structured self-review, feedback processing, and continuous correction.
-
securitymindedsolutions Bundle Audit BackendBackend application architecture audit. Checks handler hygiene, service layer patterns, data access, data contracts, error handling, code quality, testing, observability, and security against enterprise standards. Use this skill whenever the user wants to review backend code quality, check API patterns, validate architecture, or assess whether their backend follows best practices - even if they don't explicitly say 'audit'.
-
securitymindedsolutions Bundle Github Remediate VulnsScan GitHub org for Dependabot, code scanning, and secret scanning alerts. Classify findings as auto-fixable, assisted, or manual. Apply fixes with test validation, then create PRs on approval. Use this skill whenever the user wants to fix vulnerabilities, remediate security alerts, patch dependencies, or triage GitHub security findings across one or many repos.
-
senmushare Bundle Senmu Build AssuranceProduce read-only, evidence-graded POC, audit, reproduction, or disputed-cause verdicts. Not for implementation, routine review, retrospectives, or fixes.
Audited -
shad0wmazt3r Skill Bug Hunt FrameworkSecurity testing workflow assistant for recon, web, network, mobile, pwn, crypto, reverse engineering, and forensics phases.
-
ztemerbekov Bundle A1 Yandex Kit WebhooksManage Yandex KIT webhooks over its REST API: subscribe HTTPS endpoints to order status, payment and delivery events and handle the one-time signing secret. Use when creating, updating, validating or deleting KIT webhooks, verifying incoming calls, diagnosing missing order-status callbacks or migrating receipt-status automations. Russian triggers include: «настрой вебхук», «подпишись на статусы заказов», «почему не приходят уведомления о заказах», «проверь вебхук».
-
ztemerbekov Bundle A1 Yandex Kit Catalog DoctorAudit and exactly repair a Yandex KIT catalog. Use for Russian requests such as «Проверь каталог», «Проведи глубокий аудит», «Проверь группировку, карточки, медиа или коллекции», «Поставь цену 4 990 для SKU-42», «Исправь остатки по этому файлу» and exact single or bulk catalog fixes. Audits are read-only; writes require an explicit command with an exact target, operation and owner value or named authoritative source. Use a1-yandex-kit-operator instead for a fast current store signal.
-
ludovic33fr Skill Feature Ethics AuditUtiliser pour auditer une feature envisagée sur ses risques éthiques (manipulation, biais, exploitation de vulnérabilité, données). Produit un diagnostic d'exploitation potentielle, des alternatives moins exposées, et une recommandation explicite.
Audited -
byronxlg Skill Code ReviewReview code for correctness, clarity, and security.
Audited -
daydeda Skill Pdpa ExportAssemble a consolidated export of ALL data ActiveCAMT holds about a single student (PDPA subject-access request), or guide PDPA erasure — admin-only, always audit-logged, with medical detail gated to admin roles and audit_logs never included/erased. Use for a data-subject access or erasure request for one student.
-
daydeda Skill New Admin RouteScaffold a new admin API route (src/app/api/admin/**/route.ts) pre-wired with ActiveCAMT's security pattern — server-side auth() role gate, Zod validation, and a db.transaction that writes an AuditService audit log. Use when adding any admin/staff API endpoint, so the role gate and audit log can't be forgotten. For routes that read medical data, audit logging is made mandatory.
Frequently asked questions
What are Security agent skills?
Security agent skills give AI agents disciplined security workflows: code review for vulnerabilities, secret handling, dependency audits, and hardening checklists. Every skill on SkillMD also passes its own safety review before listing, with capability flags shown on each page.
Which Security skills are most installed?
Popular Security skills on SkillMD right now include audit-backend, senmu-build-assurance, antwork-voice. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do Security skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.